cloud-foundation-fabric/fast/stages-multitenant/1-resman-tenant/IAM.md

4.9 KiB

IAM bindings reference

Legend: + additive, conditional.

Folder development [#0]

members roles
tn0-gke-dev-0
serviceAccount
roles/compute.xpnAdmin
roles/logging.admin
roles/owner
roles/resourcemanager.folderAdmin
roles/resourcemanager.projectCreator

Folder development [#1]

members roles
tn0-gke-dev-0
serviceAccount
organizations/[org_id #0]/roles/serviceProjectNetworkAdmin
tn0-pf-dev-0
serviceAccount
organizations/[org_id #0]/roles/serviceProjectNetworkAdmin

Folder networking

members roles
tn0-networking-0
serviceAccount
roles/compute.xpnAdmin
roles/logging.admin
roles/owner
roles/resourcemanager.folderAdmin
roles/resourcemanager.projectCreator

Folder production [#0]

members roles
tn0-gke-prod-0
serviceAccount
roles/compute.xpnAdmin
roles/logging.admin
roles/owner
roles/resourcemanager.folderAdmin
roles/resourcemanager.projectCreator

Folder production [#1]

members roles
tn0-gke-prod-0
serviceAccount
organizations/[org_id #0]/roles/serviceProjectNetworkAdmin
tn0-pf-prod-0
serviceAccount
organizations/[org_id #0]/roles/serviceProjectNetworkAdmin

Folder sandbox

members roles
tn0-sandbox-0
serviceAccount
roles/logging.admin
roles/owner
roles/resourcemanager.folderAdmin
roles/resourcemanager.projectCreator

Folder security

members roles
tn0-security-0
serviceAccount
roles/logging.admin
roles/owner
roles/resourcemanager.folderAdmin
roles/resourcemanager.projectCreator

Folder teams

members roles
tn0-teams-0
serviceAccount
roles/compute.xpnAdmin
roles/logging.admin
roles/owner
roles/resourcemanager.folderAdmin
roles/resourcemanager.projectCreator

Folder test tenant 0

members roles
tn0-networking-0
serviceAccount
roles/compute.orgFirewallPolicyAdmin +
roles/compute.xpnAdmin +
tn0-security-0
serviceAccount
roles/accesscontextmanager.policyAdmin +